LayerZero Points to Kelp's Security Setup as Cause of $290 Million Exploit, Links Attack to North Korea's Lazarus Group
LayerZero has attributed the $290 million exploit of Kelp DAO to the protocol's single-verifier security configuration, which the company had previously advised against. According to LayerZero, the attackers, who are believed to be associated with North Korea's Lazarus Group, compromised two remote procedure call (RPC) nodes that LayerZero's verifier relied on to confirm cross-chain transactions. The attackers then replaced the binary software on these nodes with malicious versions, which reported fraudulent transactions to LayerZero's verifier while providing accurate data to other systems. To ensure the attack went undetected, the attackers launched a distributed denial-of-service (DDoS) attack on the uncompromised external RPC nodes, forcing LayerZero's verifier to failover to the compromised nodes. The attack resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack was only successful because Kelp had ignored recommendations to implement a multi-verifier setup, which would have required consensus across several independent verifiers to confirm a message. The company has confirmed that there was no contagion to other applications on the protocol and has announced that it will no longer support single-verifier configurations. The Lazarus Group has been linked to two major DeFi exploits in recent weeks, including the Drift Protocol exploit on April 1, highlighting the group's ability to adapt its tactics and exploit vulnerabilities in DeFi protocols.